Community discussions

MikroTik App
 
User avatar
Larsa
Forum Guru
Forum Guru
Topic Author
Posts: 1451
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

ZeroTier - a quick HOW-TO

Tue Apr 18, 2023 1:55 pm

A brief HOW-TO setup ZeroTier on RoS v7:

  1. Register a network in ZeroTier Central (my.zerotier.com) and use the Network ID when installing ZeroTier clients including Mikrotik devices. It's free for up to 25 devices for private use.
  2. Enable the ZeroTier "instance". Defaults will suffice.
  3. Enable the ZeroTier "interface" and specify the Network ID from #1 and the name of the interface.
  4. Each new node that is added to the network must be approved using ZeroTier Central (my.zerotier.com) before it can be used.

That's all !

Here's some more helpful info about ZeroTier that you might find interesting:
  • The ZeroTier interface appears under the regular "Interfaces" menu and is treated like any local Ethernet interface and may for example be added to the "interface list" as LAN, etc.
  • When creating a new network, ZeroTier Central autmatically picks a subnet that can be changed anytime.
  • ZeroTier Central assigns static addresses from the subnet to the clients automatically. A client can be assigned multiple addresses, for example by adding them manually.
  • To enable access to a single LAN or multiple site-to-site (mesh) networks, just add the subnets to Managed Routes in ZeroTier Central.
  • It's possible to join and use multiple ZeroTier networks simultaneously and even route traffic between them.
  • The administrative web interface called ZeroTier Central (my.zerotier.se) is a proprietary solution that runs on top of a ZeroTier controller and is operated by ZeroTier Inc. As an alternative, you may set up your own independent controller either on the router itself which is included in the ZeroTier packge or, for example in a sepearat container. When running your own controller you only get json as an administrative interface by default. To get web based administration install Zero-UI which is designed as a direct copy of the ZeroTier Central layout.
  • Complex network policies can be enforced using the ZeroTier rules engine (aka Flow Rules) that are based on capacity-based security and member classification tags. This includes rules for, for example, node addresses, tags ID's, different types of L2/L3 protocols, tcp/udp ports, etc.
  • Keep in mind that ZeroTier (at least in v1.10) is still single threaded and also depends on hardware offload for AES which hasn't been implemented on all platforms by Mikrotik (yet). Correct me if I'm wrong on this one.

Here are two useful articles that provide a good holistic overview of ZeroTier.
For a detailed walkthrough of ZeroTier see AMMO's eminent explanation:
Last edited by Larsa on Sun Jul 14, 2024 2:26 pm, edited 11 times in total.
 
User avatar
Larsa
Forum Guru
Forum Guru
Topic Author
Posts: 1451
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: ZeroTier - a quick HOW-TO

Tue Apr 18, 2023 1:56 pm

reserved.
 
fionaellie
just joined
Posts: 5
Joined: Mon Jan 15, 2024 12:06 am

Re: ZeroTier - a quick HOW-TO

Wed Aug 07, 2024 3:51 am

This is useful and gives me a bit more perspective as a new mikrotik and zerotier user. I've done the setup completely but I am still not able to reach my external zt-connected devices (members) from my LAN. Assuming I have set up all the filter, route and interface settings properly, is there anything you can think of that would prevent me from being able to reach out through the mikrotik router? I can ping members from one another, and from the router, but not from inside the router.

Who is online

Users browsing this forum: No registered users and 2 guests